HIGH
An issue was discovered in rConfig 3.9.3
Published Jan 6, 2020
7.8
HIGHCVSS 3.1
EPSS 5.74%
Description
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privileges for some binaries. This can be exploited by an attacker to bypass local security restrictions.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/156950/rConfig-3.9.4-searchField-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9202 Advisory
- https://github.com/v1k1ngfr/exploits-rconfig/blob/master/rconfig_lpe.sh x_refsource_MISCExploitThird Party Advisory
- https://raw.githubusercontent.com/v1k1ngfr/exploits/master/rconfig_lpe.sh?token= x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/156950/rConfig-3.9.4-searchField-Remote-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-9202 | Advisory | |
| https://github.com/v1k1ngfr/exploits-rconfig/blob/master/rconfig_lpe.sh | x_refsource_MISCExploitThird Party Advisory | |
| https://raw.githubusercontent.com/v1k1ngfr/exploits/master/rconfig_lpe.sh?token= | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 6, 2020
Updated Aug 5, 2024
Reserved Dec 4, 2019
Link CVE-2019-19585
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-9202 Assigner mitre
Published Jan 6, 2020
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-9202